Attacker Drains $18 Million From Ostium DeFi Vault Using a Compromised Oracle Key
An attacker drained roughly $18 million in USDC from Ostium, a decentralized perpetuals exchange built on the Arbitrum network, after gaining control of a private key used to sign the platform's price-feed data — not by exploiting a flaw in the protocol's smart contract code.
Blockchain security firm Blockaid detected the incident on July 15 and identified the mechanism: the attacker used a registered component of Ostium's automated price infrastructure, known as the PriceUpKeep forwarder, to submit oracle price reports stamped with future timestamps. Because those reports came from a key the system already trusted, they passed verification as legitimate. The attacker then ran roughly 20 looped trades that appeared, on paper, to be highly profitable, triggering automatic payouts from Ostium's liquidity vault that were, in reality, funded entirely by the manipulated price data rather than any real market movement. The vault held about $63 million at the time, meaning the theft removed close to 28% of it in one sitting.
Ostium halted all trading immediately after the exploit was detected and says the incident remains under investigation. The platform, which lets users trade tokenized real-world assets such as stocks, commodities, and forex pairs with leverage up to 200x, had raised $27.8 million from investors including General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute and GSR, and had processed a cumulative trading volume above $50 billion before the attack.
The incident fits a pattern that has made 2026 one of the worst years on record for decentralized finance exploits: more than $840 million was stolen from DeFi protocols in the first five months of the year alone, including $292 million from KelpDAO, $285 million from Drift Protocol, and $25 million from Resolv Labs in June. What links several of the largest recent cases, Ostium included, is that the attackers increasingly go after the infrastructure surrounding a protocol — the price oracles and the keys that authorize them — rather than searching for bugs in the smart contract logic itself, since that logic has typically already been through multiple audits.